CVE-2024-50532: WordPress Events Manager Pro – extended plugin <= 0.1 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1.
Security readout for executives and security teams
Plain-English summary
CVE-2024-50532 affects a WordPress plugin, Events Manager Pro – extended, through version 0.1. It can allow reflected cross-site scripting through improper output handling. A victim must interact with attacker-controlled content, but successful abuse can run script in the user’s browser context.
Executive priority
Treat this as a high-priority web application risk where the plugin is present. It is not known to be actively exploited from supplied evidence, but public WordPress exposure and no-auth prerequisites justify prompt inventory and remediation.
Technical view
The CVE describes CWE-79 reflected XSS in Jerin K Alexander events-manager-pro-extended. CVSS 3.1 is 7.1 high: network reachable, low complexity, no privileges required, user interaction required, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress sites with Events Manager Pro – extended installed at affected versions through 0.1. The source bundle does not identify affected CPEs or broader products.
Exploitation context
The record does not identify active exploitation, and KEV status is false. Exploitation requires user interaction, consistent with reflected XSS. No exploit availability or weaponized campaign is supported by the supplied sources.
Researcher notes
Evidence is narrow: CVE and Patchstack identify the vulnerable plugin, affected range, CWE-79, and CVSS vector. The supplied bundle does not name vulnerable parameters, fixed versions, exploit status, or vendor advisory details beyond the Patchstack entry.
Mitigation direction
Inventory WordPress sites for events-manager-pro-extended installations.
Check vendor or Patchstack guidance for a fixed release or official mitigation.
Disable or remove the plugin if no safe fixed version is available.
Prioritize remediation on public WordPress sites and administrator-accessible workflows.
Validation and detection
Confirm whether Events Manager Pro – extended is installed and versioned through 0.1.
Review plugin and WordPress inventories across production and staging sites.
Check web logs for unusual requests targeting plugin-related pages.
Verify remediation by confirming the plugin is updated, disabled, or removed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.